Monday, May 14, 2007

OpenKiosk Nodeview DoS

OpenKiosk, a Filipino made open source kiosk software, includes Nodeview as the server component. Nodeview is vulnerabe to a Denial of Service attack. By connecting to port 10012 of the machine running Nodeview using netcat or telnet and entering any character, a space, another character and pressing enter, an error is triggered in the qtcore4.dll. Port 10012 is used by a mini webserver accepting xmlrpc POST requests.